File name:

Vigorf.A' in file 'old-uninstaller.exe'

Full analysis: https://app.any.run/tasks/37570f33-8ca1-4e4a-8976-191e8ac84b3b
Verdict: Malicious activity
Analysis date: February 06, 2024, 14:26:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

94D1FF54A60879F38946367A26EE1041

SHA1:

3A7EFE8FB1A4E001938615BE0087D6A32CCEE6A4

SHA256:

00A4CB4D212076616447FACCF1EA573553019BDD42099AEA013BF2144AAAA4E2

SSDEEP:

3072:9GZGETVluqnvT+ESYUTsPhRbEwZoIrlnMW8paqm+LjBr9FWwHRW6/:whpHviESYrwwZoIRMWmdmWtHHR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 532)
      • Un_A.exe (PID: 752)
      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 4092)
      • Un_A.exe (PID: 2204)
  • SUSPICIOUS

    • Starts itself from another location

      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 532)
      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 4092)
    • Executable content was dropped or overwritten

      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 532)
      • Un_A.exe (PID: 752)
      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 4092)
      • Un_A.exe (PID: 2204)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Un_A.exe (PID: 752)
      • Un_A.exe (PID: 2204)
    • The process creates files with name similar to system file names

      • Un_A.exe (PID: 752)
      • Un_A.exe (PID: 2204)
  • INFO

    • Checks supported languages

      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 532)
      • Un_A.exe (PID: 752)
      • Un_A.exe (PID: 2204)
      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 4092)
    • Create files in a temporary directory

      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 532)
      • Un_A.exe (PID: 752)
      • Un_A.exe (PID: 2204)
      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 4092)
    • Reads the computer name

      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 532)
      • Un_A.exe (PID: 752)
      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 4092)
      • Un_A.exe (PID: 2204)
    • Manual execution by a user

      • Vigorf.A' in file 'old-uninstaller.exe'.exe (PID: 4092)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 23:26:14+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 473088
UninitializedDataSize: 16384
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.38.0.0
ProductVersionNumber: 6.38.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Signal Messenger, LLC
FileDescription: Private messaging from your desktop
FileVersion: 6.38.0
LegalCopyright: Copyright © 2023 Signal Messenger, LLC
ProductName: Signal
ProductVersion: 6.38.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
4
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start vigorf.a' in file 'old-uninstaller.exe'.exe un_a.exe vigorf.a' in file 'old-uninstaller.exe'.exe un_a.exe

Process information

PID
CMD
Path
Indicators
Parent process
532"C:\Users\admin\Desktop\Vigorf.A' in file 'old-uninstaller.exe'.exe" C:\Users\admin\Desktop\Vigorf.A' in file 'old-uninstaller.exe'.exe
explorer.exe
User:
admin
Company:
Signal Messenger, LLC
Integrity Level:
MEDIUM
Description:
Private messaging from your desktop
Exit code:
0
Version:
6.38.0
Modules
Images
c:\users\admin\desktop\vigorf.a' in file 'old-uninstaller.exe'.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
752"C:\Users\admin\AppData\Local\Temp\~nsu.tmp\Un_A.exe" _?=C:\Users\admin\Desktop\C:\Users\admin\AppData\Local\Temp\~nsu.tmp\Un_A.exe
Vigorf.A' in file 'old-uninstaller.exe'.exe
User:
admin
Company:
Signal Messenger, LLC
Integrity Level:
MEDIUM
Description:
Private messaging from your desktop
Exit code:
2
Version:
6.38.0
Modules
Images
c:\users\admin\appdata\local\temp\~nsu.tmp\un_a.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2204"C:\Users\admin\AppData\Local\Temp\~nsu.tmp\Un_A.exe" _?=C:\Users\admin\Desktop\C:\Users\admin\AppData\Local\Temp\~nsu.tmp\Un_A.exe
Vigorf.A' in file 'old-uninstaller.exe'.exe
User:
admin
Company:
Signal Messenger, LLC
Integrity Level:
MEDIUM
Description:
Private messaging from your desktop
Exit code:
0
Version:
6.38.0
Modules
Images
c:\users\admin\appdata\local\temp\~nsu.tmp\un_a.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
4092"C:\Users\admin\Desktop\Vigorf.A' in file 'old-uninstaller.exe'.exe" C:\Users\admin\Desktop\Vigorf.A' in file 'old-uninstaller.exe'.exe
explorer.exe
User:
admin
Company:
Signal Messenger, LLC
Integrity Level:
MEDIUM
Description:
Private messaging from your desktop
Exit code:
0
Version:
6.38.0
Modules
Images
c:\users\admin\desktop\vigorf.a' in file 'old-uninstaller.exe'.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
1 439
Read events
1 439
Write events
0
Delete events
0

Modification events

No data
Executable files
4
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
4092Vigorf.A' in file 'old-uninstaller.exe'.exeC:\Users\admin\AppData\Local\Temp\~nsu.tmp\Un_A.exeexecutable
MD5:94D1FF54A60879F38946367A26EE1041
SHA256:00A4CB4D212076616447FACCF1EA573553019BDD42099AEA013BF2144AAAA4E2
2204Un_A.exeC:\Users\admin\AppData\Local\Temp\nsa83AD.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
752Un_A.exeC:\Users\admin\AppData\Local\Temp\nsu3629.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
532Vigorf.A' in file 'old-uninstaller.exe'.exeC:\Users\admin\AppData\Local\Temp\~nsu.tmp\Un_A.exeexecutable
MD5:94D1FF54A60879F38946367A26EE1041
SHA256:00A4CB4D212076616447FACCF1EA573553019BDD42099AEA013BF2144AAAA4E2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info